Unix Technical Forum

SEO

vBulletin Search Engine Optimization


Go Back   Unix Technical Forum > Unix Operating Systems > Sco Unix

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-06-2008, 02:02 PM
Boyd Lynn Gerber
 
Posts: n/a
Default smtp setup and spam

Hello,

With the setup I use with SPF (around 15-20,000 emails per day to me
or the aliases that come to me) and ...

postfix or sendmail, sometimes exim
amavis-new
spamassassin
python-pydns
python-pydspam
python-pyspf
python-pygossip
python-pysrs

About 85% of emails are rejected before the smtp data stage saving a lot
of more expensive resources.

Once through the above I get 4-5 emails that are not taged that are spam
and 2-3 false positives. My data basis are trained and I use razor.
The below is from a header that has been through spamassassin and marked
as spam.


1.4 MSGID_FROM_MTA_ID Message-Id for external message added locally
0.0 UNPARSEABLE_RELAY Informational: message has unparseable relay
lines
3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
[score: 1.0000]
1.5 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
0.5 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.5 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
1.6 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see
<http://www.spamcop.net/bl.shtml?220.92.37.23>]
3.9 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[220.92.37.23 listed in sbl-xbl.spamhaus.org]
1.6 URIBL_SBL Contains an URL listed in the SBL blocklist
[URIs: conitaf.com.cn]
3.0 URIBL_OB_SURBL Contains an URL listed in the OB SURBL
blocklist

It is then run through sa-learn to report it and auto deleted. The IP
that the email came from reputation is then dinged for the spam. The same
applies for a valid email. Domains and IP addresses are blacklisted at
certain levels. This is all configurable. So I really recommend these
tools.


--
Boyd Gerber <gerberb@zenez.com>
ZENEZ 1042 East Fort Union #135, Midvale Utah 84047
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 03-06-2008, 02:02 PM
Nico Kadel-Garcia
 
Posts: n/a
Default Re: smtp setup and spam

On 6 Mar, 08:25, Boyd Lynn Gerber <gerb...@zenez.com> wrote:
> Hello,
>
> With the setup I use with SPF (around 15-20,000 emails per day to me
> or the aliases that come to me) and ...
>
> postfix or sendmail, sometimes exim
> amavis-new
> spamassassin
> python-pydns
> python-pydspam
> python-pyspf
> python-pygossip
> python-pysrs
>
> About 85% of emails are rejected before the smtp data stage saving a lot
> of more expensive resources.
>
> Once through the above I get 4-5 emails that are not taged that are spam
> and 2-3 false positives. *My data basis are trained and I use razor.
> The below is from a header that has been through spamassassin and marked
> as spam.
>
> 1.4 MSGID_FROM_MTA_ID * * *Message-Id for external message added locally
> *0.0 UNPARSEABLE_RELAY * * *Informational: message has unparseablerelay
> lines
> *3.5 BAYES_99 * * * * * * * BODY: Bayesian spam probability is 99 to 100%
> * * * * * * * * * * * * * * [score: 1.0000]
> *1.5 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
> * * * * * * * * * * * * * * above 50%
> * * * * * * * * * * * * * * [cf: 100]
> *0.5 RAZOR2_CHECK * * * * * Listed in Razor2 (http://razor.sf.net/)
> *0.5 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
> * * * * * * * * * * * * * * [cf: 100]
> *1.6 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
> * * * * * * * * [Blocked - see
> <http://www.spamcop.net/bl.shtml?220.92.37.23>]
> *3.9 RCVD_IN_XBL * * * * * *RBL: Received via a relay in Spamhaus XBL
> * * * * * * * * * * * * * * [220.92.37.23 listed in sbl-xbl.spamhaus.org]
> *1.6 URIBL_SBL * * * * * * *Contains an URL listed in the SBL blocklist
> * * * * * * * * * * * * * * [URIs: conitaf.com..cn]
> *3.0 URIBL_OB_SURBL * * * * Contains an URL listed in the OB SURBL
> blocklist
>
> It is then run through sa-learn to report it and auto deleted. *The IP
> that the email came from reputation is then dinged for the spam. *The same
> applies for a valid email. *Domains and IP addresses are blacklisted at
> certain levels. *This is all configurable. *So I really recommend these
> tools.


For more individualized and even more effective spam blocking, you
might look at CRM114 over at Sourceforge. Some spammers tune their
spam to get past Spamassassin, but they haven't had much luck yet with
crm114.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 07:17 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145